Rsync 3.5.0 has been released with fixes for 33 vulnerabilities affecting the widely used file synchronization utility, including several critical and high-severity issues in the rsync daemon, file handling, path validation, logging, proxy protocol support, and the restricted rrsync wrapper. The most serious flaws include client IP spoofing when proxy protocol = true is enabled, command-execution risks tied to RSYNC_CONNECT_PROG and rsync-ssl, arbitrary file overwrite conditions involving symlink and path-handling weaknesses, and bypasses that undermine rrsync restrictions.
The update also addresses information disclosure, denial-of-service conditions, access-control weaknesses, and file-handling risks that can arise in privileged or chroot-adjacent deployments. Reported mitigations include restricting which hosts may use proxy protocol, avoiding unsafe privileged usage patterns, tightening file-opening behavior with protections such as O_NOFOLLOW, and reviewing DNS-dependent controls such as hosts deny logic that may be bypassed under some conditions.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Backport patch sets for rsync versions 3.2.7 and 3.4.1 were sent to distro maintainers via distros@vs.openwall.org the week before the 3.5.0 announcement. The project also published GitHub security patch branches for both older versions to support downstream updates.
A new Rsync 3.5.0 release was published, addressing 33 security vulnerabilities across daemon behavior, proxy protocol handling, file and path processing, logging, access controls, and the restricted rrsync wrapper. The reported issues include critical, high, and medium-severity flaws, with mitigations such as restricting proxy protocol hosts and using safer file-opening practices like O_NOFOLLOW.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourceseclists.org
Open sourceopennet.me
Open sourceopennet.ru
Open sourcevulncheck.com
Open sourcersync.samba.org
Open sourcemail-archive.com
Open sourcedownload.samba.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.